VulnerabilityModified
CVE-2019-8445
Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time information via a missing permissions check.
MEDIUM 5.3EPSS 2.71%
Does this matter?
Lower severity and a low EPSS score (2.71%). Track it; it rarely justifies an emergency change on its own.
Description
Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time information via a missing permissions check.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 2.71% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863, CWE-862
- Affected
- atlassian/jira server
- Source
- security@atlassian.com
References
- https://jira.atlassian.com/browse/JRASERVER-69778Vendor Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0840Third Party Advisory
- https://jira.atlassian.com/browse/JRASERVER-69778Vendor Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0840Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.